WarDriving & Wireless Penetration Testing

With operating system (OS) X, WarDriving and Wireless Local Area Network (WLAN) penetration testing have excellent wireless support and several tools to make these tasks easy.
The first part of this chapter describes the steps necessary to configure and utilize the KisMAC WLAN discovery tool in order to successfully WarDrive. (For additional information regarding WarDriving, see Chapter 1.) The second part of this chapter describes how to use the information obtained during a WarDrive, and goes on to detail how a penetration tester can further utilize KisMAC to successfully penetrate a customer s wireless network.
KisMAC is the best WarDriving and WLAN discovery and penetration testing tool available on any platform, and is available for free at http://kismac.binaervarianz.de/. Most WarDriving applications provide the capability to discover networks in either active mode or passive mode; KisMAC provides both. On other platforms, WarDriving tools such as Kismet for Linux and NetStumbler for Windows only provide the capability to discover WLANs. KisMAC is unique because it also includes the functionality that a penetration tester needs to attack and compromise found networks.
| Tool | Platform | Scan Type | Attack Capability |
|---|---|---|---|
| NetStumbler | Windows | Active | No |
| Kismet | Linux | Passive | No |
| KisMAC | OS X | Active/Passive | Yes |
Once KisMAC has been downloaded and installed, it is relatively easy-to-use. The first thing you need to do is load KisMAC, which is done by clicking on the KisMAC icon (see Figure...